PaidIndexRequest a signed DPA
Data Processing Addendum

Business data, handled carefully.

Version dated September 8, 2026

This DPA is available when Media Yard LLC processes personal data on behalf of a business customer.

How this becomes effective: This DPA is not independently effective merely because it is viewed. It applies when an order form or other written agreement with Media Yard LLC incorporates it, or when both parties sign it. Request an execution copy through Support.

1. Parties and scope

This Data Processing Addendum (“DPA”) forms part of the agreement (“Agreement”) between the customer identified in an applicable order form (“Customer”) and Media Yard LLC (“Media Yard”) for PaidIndex services. It applies only to personal data Media Yard processes as a processor or service provider on Customer’s behalf (“Customer Personal Data”). Each party remains responsible for data it processes as an independent controller.

2. Roles and instructions

Customer is the controller/business and Media Yard is the processor/service provider, as those terms or their equivalents are defined by applicable data-protection law. Media Yard will process Customer Personal Data only to provide, secure, support, and improve the contracted service; comply with documented instructions in the Agreement; and meet legal obligations. Media Yard will notify Customer if an instruction appears to violate applicable data-protection law, unless prohibited.

3. Customer responsibilities

Customer will provide lawful instructions, required notices, and a valid legal basis for processing. Customer will not submit data prohibited by the Agreement or unnecessary sensitive information and will configure and use the service appropriately.

4. Confidentiality and security

Media Yard will ensure personnel authorized to process Customer Personal Data are subject to appropriate confidentiality duties. Taking into account the nature and risk of processing, Media Yard will maintain reasonable administrative, technical, and organizational measures designed to protect confidentiality, integrity, and availability, including access controls, encrypted transport, private document storage, logging, and incident response practices.

5. Subprocessors

Customer authorizes the use of subprocessors needed to provide the service. Current core subprocessors are Cloudflare, Inc. (hosting, security, and object storage); Supabase, Inc. and its infrastructure providers (authentication and database); Resend, Inc. (transactional email); and, if billing is enabled for Customer, Stripe, Inc. (payments). Media Yard will impose data-protection obligations appropriate to each subprocessor’s services and remain responsible for its obligations under this DPA.

6. Requests and assistance

Taking into account the nature of processing, Media Yard will provide reasonable assistance for Customer to respond to verified data-subject requests and meet applicable obligations concerning security, breach notification, impact assessments, and regulatory consultations. Customer is responsible for responding to requests as controller.

7. Security incidents

Media Yard will notify Customer without undue delay after becoming aware of a confirmed breach of Customer Personal Data and provide information reasonably available to help Customer meet notification duties. Notification is not an admission of fault or liability.

8. Return and deletion

On termination or written request, Media Yard will delete or return Customer Personal Data within a reasonable period, unless retention is required by law or maintained temporarily in protected backups. The service currently targets 30-day retention for uploaded source documents, subject to the exceptions described in the Privacy Policy.

9. Audits

Media Yard will provide information reasonably necessary to demonstrate compliance with this DPA. If that information is insufficient, Customer may request a reasonable audit no more than once annually, subject to confidentiality, security, scope, scheduling, and cost protections. Additional audits may occur following a material security incident or when required by a regulator.

10. International transfers

The service is operated from the United States. If Customer Personal Data subject to restricted-transfer rules is transferred to a country without an applicable adequacy mechanism, the parties will implement a lawful transfer mechanism. Where agreed and applicable, the then-current European Commission Standard Contractual Clauses or UK transfer addendum will be incorporated with the appropriate modules and completed annexes.

11. U.S. state privacy terms

To the extent applicable, Media Yard acts as Customer’s processor, contractor, or service provider; will not sell or share Customer Personal Data or use it for targeted advertising; will not retain, use, or disclose it outside the direct business relationship except as permitted by law and the Agreement; and will provide the same level of privacy protection required of Customer for the delegated processing.

12. Priority and liability

If this DPA conflicts with the Agreement regarding processing of Customer Personal Data, this DPA controls. Liability under this DPA is subject to the Agreement’s limitations unless applicable law prohibits that limitation.

Annex A — Processing details

  • Subject matter: operation and support of PaidIndex for Customer.
  • Duration: the Agreement plus authorized retention and deletion periods.
  • Nature and purpose: hosting, authentication, storage, analysis, support, security, email, and Customer-requested functionality.
  • Data subjects: Customer users, personnel, contributors, support contacts, and persons whose data Customer lawfully submits.
  • Data types: identifiers, account data, support communications, service usage, pricing submissions, source documents, and technical/security logs.
  • Sensitive data: not intended; Customer must not submit sensitive data unless expressly agreed in writing.
© 2026 Media Yard LLC